SpyFalcon

Discussion in 'Malware Help (A Specialist Will Reply)' started by aleem, Mar 16, 2006.

  1. aleem

    aleem Private E-2

    "To remove SpyFalcon, follow the below steps carefully.

    First, make sure you have followed the steps in this link: How to view hidden, system files & folders!

    Now copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixfalcon.reg and then click save. it to your Desktop. We will use it later after a reboot into safe mode.
    Quote:
    REGEDIT4
    [-HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{D1A2E7CD-F5C1-21A8-CA2C-13D0AC72D19D}]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
    "{D1A2E7CD-F5C1-21A8-CA2C-13D0AC72D19D}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpyFalcon"=-

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{C9FA1DC9-1FB3-C2A8-2F1A-DC1A33E7AF9D}"=-

    [-HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{C9FA1DC9-1FB3-C2A8-2F1A-DC1A33E7AF9D}]


    Now download smitRem.exe written by noahdfear and save the file to your Desktop.
    Double click on the smitRem.exe file to extract it to it's own folder on the desktop. (this should be the default selection). Do not run the program yet!
    Now you will need to print or save these instructions locally (to a text file on your Desktop) for later reference. This is necessary because you must not have any browers open and must not connect to the internet while following the below steps
    .
    Now disconnect your cable to the internet (physically unplug it).
    After saving the instructions, reboot into Safe mode
    Now once in safe mode, goto Add/Remove programs and uninstall SpyFalcon.
    Now double-click on the fixfalcon.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Run Windows Explorer by right clicking Start & Select Explore
    Navigate to C:\Windows\system32 (or C:\Winnt\System32 based on how and which OS you installed.)
    Look for the following two files dxmpp.dll and/or ginuerep.dll in the system32 folder and right click on them and select delete. If they will not delete now. We will retry later.
    Now open the smitRem folder on your Deskop, double click on it to access the folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.
    The tool will create a log named smitfiles.txt in the root of the drive that you ran the batch file on, eg; Local Disk C: or partition where your operating system is installed. Upload this file later after reboot.
    Now reboot your system into normal mode.
    If you had any problems deleting the dxmpp.dll and/or ginuerep.dll files, try it again now.
    Also delete this folder if found: C:\Program Files\SpyFalcon
    Reconnect your cable to the internet.
    Now attached your smitfiles.txt log to a message and provide information about the steps above and what your current status is with SpyFalcon."


    I am having problems with the bolded step. When I run this it says that invaild command. Note that in MSDOS I cant even run ipconfig, ping, tracerout etc.

    I want to know if i really got rid of SpyFalcon. This is what I did:
    First I booted into safe mode.
    Then I ran Panda Titanium 2006 Antivirus and Antispyware
    Then i ran Windows Defender
    Then I went into the registry using regedit HKEY_CURRENT_USER\Software
    and deleted the Key Name SpyFalcon.


    I want to make sure that all that God-for-saken Software is off my computer. LOL
     
  2. aleem

    aleem Private E-2

    Plus I reseted my Browser settings and went in to the registry and fixed the keys.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post HijackThis logs without having run the steps in the READ & RUN ME First sticky thread. HJT logs do not always show information related to Spy Falcon problems. So just looking at a HijackThis log does not mean very much.

    If you were not able to complete the steps in the SpyFalcon procedure and have not run SmitRem, you may still have some files related to SpyFalcon hanging around.

    Is your system currently displaying any malware symptoms?
     
  4. aleem

    aleem Private E-2

    Please close thread
    I finally figured out why MSDOS was not working my path was wrong.
    The spyware problem has also been fixed.
    This is a great forum, the moderators know what they are doing.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We do not normally close threads! Happy to hear you have your problems resolved.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds